UNKNOWNCVE-2022-25278

Access bypass in Drupal Core

Platform

drupal

Component

drupal

Fixed in

9.3.19

Drupal core form API evaluates form element access incorrectly. This can lead to a user being able to alter data they should not have access to.

How to fix

No official patch available. Check for workarounds or monitor for updates.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free